Open
Cached
·
just now
8
directives
Content-Security-Policy
Content-Security-Policy: default-src 'self'; script-src 'unsafe-inline' blob: https://factsmgt.com https://*.cdn.us2.com *.addevent.com https://vimeo.com https://js-na2.hubspot.com https://js-na2.hsforms.net https://js-na2.hs-scripts.com https://js-na2.hsadspixel.net https://js-na2.hsadspixel.net/fb.js https://js.hubspot.com/content-embed/v1.js https://js.hs-analytics.net https://static.hsappstatic.net https://js-na2.hs-analytics.net https://js-na2.hscollectedforms.net https://js-na2.hs-banner.com transcend-cdn.com assets.apollo.io tracking-api.g2.com js.ipredictive.com *.storylane.io nelnet.jotform.com *.gstatic.com snap.licdn.com embed.eventbookings.com *.vimeo.com 'self' *.cookielaw.org *.hotjar.com *.google-analytics.com *.google.com ajax.googleapis.com *.facebook.net googleads.g.doubleclick.net *.facebook.com addevent.com static.addtoany.com cdnjs.cloudflare.com stackpath.bootstrapcdn.com *.pardot.com *.googletagmanager.com whova.com *.factsmgt.com factsmgt.com *.cloudfront.net *.googleadservices.com 'unsafe-eval'; style-src https://*.cdn.us2.com *.bootstrapcdn.com cdnjs.cloudflare.com transcend-cdn.com www.googletagmanager.com https://use.typekit.net https://p.typekit.net https://7052064.fs1.hubspotusercontent-na1.net 'unsafe-inline' *.fontawesome.com 'self' *.googleapis.com *.cloudfront.net; img-src 'self' https://*.cdn.us2.com *.google.com *.google-analytics.com https://forms-na2.hsforms.com https://track.hubspot.com https://cta-na2.hubspot.com https://static.hsappstatic.net https://static.hubspot.com https://track-na2.hubspot.com https://perf-na2.hsforms.com https://connect.facebook.net *.googletagmanager.com googleads.g.doubleclick.net i.vimeocdn.com ct.capterra.com px.ads.linkedin.com *.cookielaw.org *.w.org *.facebook.com *.gravatar.com *.nelnet.net data: *.s3.amazonaws.com *.cloudfront.net; connect-src 'self' *.bugsnag.com *; font-src *.fontawesome.com *.gstatic.com 'self' * data:; media-src 'self'; frame-src *.pardot.com https://forms-na2.hsforms.com *.hs-sites-na2.com info.factsmgt.com.au ad.ipredictive.com nelnet.jotform.com *.storylane.io embed.eventbookings.com *.evnt.is *.google.com *.vimeo.com *.factsmgt.com www.googletagmanager.com *.addtoany.com *.hotjar.com factsmgt.com *.facebook.com *.doubleclick.net *.youtube.com https://whova.com *.whova.com;
default-src
Keyword
—
'self'
script-src
Keyword
—
'unsafe-inline'
script-src
Scheme
—
blob:
script-src
Keyword
—
'self'
script-src
Keyword
—
'unsafe-eval'
style-src
Keyword
—
'unsafe-inline'
style-src
Keyword
—
'self'
img-src
Keyword
—
'self'
img-src
Scheme
—
data:
connect-src
Keyword
—
'self'
connect-src
Host
—
*
font-src
Keyword
—
'self'
font-src
Host
—
*
font-src
Scheme
—
data:
media-src
Keyword
—
'self'
frame-src
Host
—
Content-Security-Policy-Report-Only
No report-only CSP headers found.